The goal of the Analyst is to provide valid evidence for the investigation in progress. Evidence is:
To do this, the Analyst can perform the following procedures:
To select and retrieve important evidence:
In the File System section, during remote tapping, explore the device hard disks searching for files to be downloaded.See "Retrieve evidence from devices (File System)"
In the Dashboard section, add the operation, targets and agents to be monitored to the dashboard.
See "Monitoring evidence (Dashboard)"
In the Alerting section, set rules to be alerted when evidence of special interest arrives and to tag evidence according to relevance.
See "Target alert (Alerting)"
To analyze, select and export evidence:
In the Evidence section, analyze evidence and tag them according to relevance and whether or not they are to be exported.
See "Evidence analysis (Evidence)".
For evidence of special interest, move on to detailed analysis.
See "Evidence details"
In the Evidence section, export useful evidence.
In the File System section, export the hard disk structure
See "Retrieve evidence from devices (File System)"
RCS8.2 | User's and Installation Guide | © COPYRIGHT 2012